GIAC GEIR Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Enterprise Incident Response |
| Exam Number: | GEIR |
| Certificate Validity Period: | 4 years |
| Exam Format: | Multiple Choice, Performance-Based Questions |
| Passing Score: | 72% |
| Real Exam Qty: | 82 |
| Exam Price: | $999 USD |
| Exam Duration: | 180 minutes |
| Related Certifications: | GIAC Certified Forensic Analyst (GCFA) GIAC Certified Incident Handler (GCIH) |
| Available Languages: | English |
| Recommended Training: | SANS FOR608: Enterprise-Class Incident Response & Threat Hunting |
| Exam Registration: | GIAC Official Registration PearsonVUE Scheduling |
| Sample Questions: | GIAC GEIR Sample Questions |
| Exam Way: | Web-based proctored exam; remote via ProctorU or onsite at PearsonVUE test centers |
| Pre Condition: | No mandatory prerequisites; recommended experience in incident response, digital forensics, or cybersecurity operations |
| Official Syllabus URL: | https://www.giac.org/certifications/enterprise-incident-responder-geir/ |
GIAC GEIR Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Automation and Tooling | 12% | - Orchestration and automation
|
| Topic 2: Network and Cloud Response | 20% | - Cloud environment investigation
|
| Topic 3: Incident Response Foundations | 15% | - IR frameworks and methodologies
|
| Topic 4: Large-Scale Incident Management | 15% | - Legal, compliance, and reporting
|
| Topic 5: Threat Hunting and Advanced Analysis | 18% | - Proactive threat hunting methodologies
|
| Topic 6: Endpoint Analysis and Response | 20% | - Windows systems analysis
|
GIAC Enterprise Incident Response Sample Questions:
What types of data sources are instrumental in scoping malware spread within an enterprise network?
Response:
- A. DHCP logs
- B. Endpoint detection and response systems
- C. Application performance management tools
- D. Employee performance tracking systems
Correct Answer: A,B 🗳️
Select the types of logs that would be most helpful in scoping a data exfiltration incident.
Response:
- A. Web application firewall logs
- B. Server load balancer logs
- C. Change management logs
- D. System event logs
- E. Network flow data
Correct Answer: A,D,E 🗳️
What is a "container image"?
Response:
- A. A graphical representation of a container
- B. A snapshot of a virtual machine
- C. A backup copy of a database
- D. A static file with executable code and dependencies
Correct Answer: D 🗳️
Which protocol is used by macOS for system-wide logging and how is it accessed?
Response:
- A. NFS, accessed through System Preferences
- B. Syslog, accessed through Console
- C. ASL, accessed through Console
- D. SMB, accessed through Terminal
Correct Answer: C 🗳️
Which of the following is a foundational strategy for responding to a container-based incident?
Response:
- A. Shutting down the entire network
- B. Following a pre-defined incident response plan
- C. Ignoring the incident
- D. Patching all software immediately
Correct Answer: B 🗳️
We're so confident of our products that we provide no hassle product exchange.


By Marina

